2. After a user installs a mobile application from an advertisement, the phone's battery dies a few hours later, and it is hot to touch, even when not in use. Which of the following should a technician do first?

Answer: C

Explanation:

Run a mobile malware scan on the phone.

Conducting a mobile malware scan is the first step a technician should take when a user's phone experiences rapid battery drain and overheating after installing an application. This action helps identify any malicious software that may be causing these issues.

A) Check for unauthorized device administrators.

While checking for unauthorized device administrators is an important security measure, it is not the immediate action to take in this scenario. The symptoms described suggest a potential malware infection, which should be addressed first through a scan.

B) Contact the software developer.

Contacting the software developer may provide insights into the application, but it does not address the immediate concern of the device's performance issues. The technician should first assess whether malware is present before seeking external support.

C) Run a mobile malware scan on the phone.

Running a mobile malware scan is crucial as it directly targets the potential cause of the phone's overheating and rapid battery drain. This proactive step can help detect harmful applications that may have been inadvertently installed alongside the legitimate app.

D) Ensure appropriate MDM policies are applied.

While applying Mobile Device Management (MDM) policies is essential for overall device security, it is not the first action to take in response to the immediate symptoms presented. The technician should first investigate the specific incident of malfunction before implementing broader policies.

Conclusion

Running a mobile malware scan is the most effective first step in diagnosing the issues of battery drain and overheating, as it addresses the potential presence of harmful software directly linked to the newly installed application. Other options, while important in the broader context of device security, do not directly resolve the immediate problem, making them less suitable as initial actions.